PkgRadar

PyPI · pypi.org

drydock-agent

Py Runtime Dynamic Dangerous Import: Dynamic __import__('os') — reflection bypass for static checks.

Why PkgRadar flagged 2.10.34

SeveritySignalEvidence
highPy Runtime Dynamic Dangerous ImportDynamic __import__('os') — reflection bypass for static checks. · drydock_agent-2.10.34/drydock/core/hooks.py

Scanned versions

VersionVerdictScoreScanned (UTC)
2.10.34High risk302026-06-11
2.10.33High risk302026-06-11
2.10.32High risk302026-06-11
2.10.30High risk302026-06-11
2.10.29High risk302026-06-10
2.10.28High risk302026-06-10
2.10.23High risk302026-06-10
2.10.16High risk302026-06-10
2.10.15High risk302026-06-10
2.10.14High risk302026-06-09
2.10.13High risk302026-06-09

Block this in CI

PkgRadar gates drydock-agent (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi drydock-agent==2.10.34